首页> 外文期刊>Future generation computer systems >A web-based cooperative tool for risk management with adaptive security
【24h】

A web-based cooperative tool for risk management with adaptive security

机译:基于Web的协作工具,用于具有自适应安全性的风险管理

获取原文
获取原文并翻译 | 示例
           

摘要

Risk management can benefit from Web-based tools fostering actions for treating risks in an environment, while having several individuals collaborating to face the endeavors related to risks. During the intervention, the security rules in place to preserve resources from unauthorized access, might need to be modified on the fly, e.g., increasing the privileges of risk managers or letting rescue teams view the exact position of the victims. Modifications should respect the overall security policies and avoid security conflicts. This paper presents a dynamic access control model for environmental risks involving physical resources. Data structures included in our Web application to represent both risk and security are given. To keep the dynamic security rules compliant with overall organization security objectives, we consider rules grouped in Access Control Domains so that changes do not create security conflicts during collaboration in risk management Considering work environments as an example, risk and access control models are introduced. Security is built on the ABAC (Attribute Based Access Control) paradigm. A Risk Management System (RMS) is illustrated: it captures events, signals potential risks, and outputs strategies to prevent the risk. Dynamic authorization is included in the RMS to vary subjects' privileges on physical resources based on risk level, people position and so on. These concepts are implemented in a prototype Web application appearing as a Web Dashboard for risk management.
机译:风险管理可以从基于Web的工具中受益,这些工具可以促进处理环境中的风险的措施,同时让多个人进行协作以应对与风险相关的工作。在干预期间,可能需要即时修改用于保护资源以防止未经授权访问的安全规则,例如,增加风险管理人员的特权或让救援队查看受害者的确切位置。修改应遵守整体安全策略,并避免安全冲突。本文提出了一种涉及物理资源的环境风险的动态访问控制模型。给出了Web应用程序中包含的表示风险和安全性的数据结构。为了使动态安全规则符合组织的总体安全目标,我们考虑将规则分组在“访问控制域”中,以便在风险管理协作期间更改不会造成安全冲突。以工作环境为例,介绍了风险和访问控制模型。安全性建立在ABAC(基于属性的访问控制)范例上。说明了一个风险管理系统(RMS):它捕获事件,发出潜在风险的信号并输出​​预防风险的策略。 RMS中包含动态授权,可根据风险级别,人员位置等来更改主体对物理资源的特权。这些概念在作为Web Dashboard进行风险管理的原型Web应用程序中实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号